cyber:vulnerabilite:cross_site_request_forgery
Différences
Ci-dessous, les différences entre deux révisions de la page.
Les deux révisions précédentesRévision précédente | |||
cyber:vulnerabilite:cross_site_request_forgery [2025/07/03 12:22] – [Exemple 2] admin | cyber:vulnerabilite:cross_site_request_forgery [2025/07/03 12:23] (Version actuelle) – [CWEs] admin | ||
---|---|---|---|
Ligne 168: | Ligne 168: | ||
The web application does not, or can not, sufficiently verify whether a well-formed, | The web application does not, or can not, sufficiently verify whether a well-formed, | ||
- | CWE-306 : Missing Authentication for Critical Function | + | * [[https:// |
The software does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources. | The software does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources. | ||
- | CWE-664 : Improper Control of a Resource Through its Lifetime | + | * [[https:// |
The software does not maintain or incorrectly maintains control over a resource throughout its lifetime of creation, use, and release. | The software does not maintain or incorrectly maintains control over a resource throughout its lifetime of creation, use, and release. | ||
- | CWE-732 : Incorrect Permission Assignment for Critical Resource | + | * [[https:// |
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. | The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. | ||
- | CWE-1275 : Sensitive Cookie with Improper SameSite Attribute | + | * [[https:// |
The SameSite attribute for sensitive cookies is not set, or an insecure value is used. | The SameSite attribute for sensitive cookies is not set, or an insecure value is used. | ||
- | References | + | ====== |
- | URL | + | |
- | https:// | + | URL : |
- | https:// | + | |
- | https:// | + | |
+ | | ||
====== Retour fiches vulnérabilités ====== | ====== Retour fiches vulnérabilités ====== | ||
* [[cyber: | * [[cyber: | ||
cyber/vulnerabilite/cross_site_request_forgery.txt · Dernière modification : 2025/07/03 12:23 de admin